VerdantBamboo Targets Linux Systems with Customized Malware Arsenal

Meet VerdantBamboo, a stealthy threat actor that infiltrated Linux and BSD systems, hiding in plain sight for 18 months by cleverly evading detection and morphing its malware arsenal to blend in. Its sophisticated attacks went undetected until Volexity's incident response team uncovered the intrusion, revealing a complex trail that led…

https://osintsights.com/verdantbamboo-targets-linux-systems-with-customized-malware-arsenal?utm_source=mastodon&utm_medium=social

#Verdantbamboo #Linux #CustomizedMalware #Microsoft365 #Egnyte

VerdantBamboo Targets Linux Systems with Customized Malware Arsenal

Learn how VerdantBamboo targets Linux systems with customized malware, track their moves & protect your network - discover the latest threat intel now.

OSINTSights

VerdantBamboo (UNC5221): il gruppo APT cinese che resta invisibile per 18 mesi con tre backdoor inedite

Volexity ricostruisce un'intrusione durata 18 mesi da parte del gruppo APT cinese VerdantBamboo/UNC5221. Tre backdoor inedite — BRICKSTORM, PLENET e AGENTPSD — deployate su appliance senza EDR per bypassare le Conditional Access Policy di Microsoft 365. Il gruppo è tornato pochi giorni dopo la remediation.

https://insicurezzadigitale.com/verdantbamboo-unc5221-il-gruppo-apt-cinese-che-resta-invisibile-per-18-mesi-con-tre-backdoor-inedite/

Chinese APT deploys new malware to keep access to hacked networks

A Chinese espionage group tracked as UNC5221 has been accessing Microsoft 365 environments using the Brickstorm backdoor and previously undocumented malware named Plenet and AgentPSD.

BleepingComputer
VerdantBamboo: Just Another BRICKSTORM in the Firewall

In September 2025, Volexity conducted an incident response engagement that began after suspicious network traffic was observed from a Linux-based virtual machine appliance on a customer’s network. The virtual machine was an Egnyte Storage Sync system, which is designed to facilitate sync local on-premise files with the cloud. Volexity discovered that instead of connecting to a domain affiliated with Egnyte, the appliance was connecting to a threat-actor-controlled domain behind Cloudflare IP addresses.

Volexity

Chinese APT Exploits New Malware to Prolong Network Access

A Chinese-linked espionage group, tracked as UNC5221 or VerdantBamboo, exploited new malware to secretly maintain access to US networks for over 18 months, evading detection by blending in with legitimate traffic. The attackers used a sophisticated backdoor called Brickstorm to prolong their stay undetected.

https://osintsights.com/chinese-apt-exploits-new-malware-to-prolong-network-access?utm_source=mastodon&utm_medium=social

#ChineseApt #MalwareOperations #NationState #Unc5221 #Verdantbamboo

Chinese APT Exploits New Malware to Prolong Network Access

Learn how Chinese APT group UNC5221 uses new malware to prolong network access and evade detection, and take steps to protect your organization now.

OSINTSights